[Forgot Password]
Login  Register Subscribe

30389

 
 

423868

 
 

244625

 
 

909

 
 

193379

 
 

277

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2014-9376Date: (C)2014-12-22   (M)2023-12-22


Integer underflow in Ettercap 0.8.1 allows remote attackers to cause a denial of service (out-of-bounds write) and possibly execute arbitrary code via a small (1) size variable value in the dissector_dhcp function in dissectors/ec_dhcp.c, (2) length value to the dissector_gg function in dissectors/ec_gg.c, or (3) string length to the get_decode_len function in ec_utils.c or a request without a (4) username or (5) password to the dissector_TN3270 function in dissectors/ec_TN3270.c.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 7.5
Exploit Score: 10.0
Impact Score: 6.4
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: NONE
Confidentiality: PARTIAL
Integrity: PARTIAL
Availability: PARTIAL
  
Reference:
http://www.securityfocus.com/archive/1/534248/100/0/threaded
BID-71696
GLSA-201505-01
https://github.com/Ettercap/ettercap/pull/602
https://github.com/Ettercap/ettercap/pull/605
https://github.com/Ettercap/ettercap/pull/606
https://github.com/Ettercap/ettercap/pull/609
https://www.obrela.com/home/security-labs/advisories/osi-advisory-osi-1402/

OVAL    5
oval:org.secpod.oval:def:108246
oval:org.secpod.oval:def:108260
oval:org.secpod.oval:def:108560
oval:org.secpod.oval:def:108561
...

© SecPod Technologies